Skip to main content

Vendor/product archive

jenkins / code_coverage_api CVEs

Beta · best-effort

3 CVEs tagged to jenkins / code_coverage_api0 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2021-21677

Published Aug 31, 2021

Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java objects it deserializes from disk, resulting in a remote code…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2172

Published Apr 7, 2020

Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2106

Published Jan 29, 2020

Jenkins Code Coverage API Plugin 1.1.2 and earlier does not escape the filename of the coverage report used in its view, resulting in a stored XSS vulnerability exploitable by use…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1